Health & Hospital Corporation Privacy Officer
Listed on 2026-02-03
-
Healthcare
Healthcare Compliance, Emergency Crisis Mgmt/ Disaster Relief
Location: Indianapolis
Select how often (in days) to receive an alert:
Health and Hospital Corporation is an organization that celebrates diversity, and seeks to employ a diverse workforce. We actively encourage all individuals to apply for employment and to seek advancement opportunities. Health and Hospital Corporation also provides reasonable accommodations to qualified individuals with disabilities as required by law. For additional questions please contact us at: hrmail.
Job Role SummaryImplements, manages, and continuously improves HHC’s privacy program and aligns privacy programs across HHC divisions (MCPHD, IEMS, Eskenazi Health). Serves as the organization’s subject matter expert on privacy matters (including information blocking), leads privacy governance, and ensures compliance with privacy regulations through policy development, training, monitoring, and incident response.
Day in Life:
Provides day-to-day privacy leadership through advising leaders and staff, coordinating privacy governance activities, monitoring compliance risks, delivering training, and investigating/responding to privacy complaints or potential breaches.
1) Privacy Program Leadership & Governance — 30%
- Develops, implements, monitors, trains on, and reports on the privacy program for HHC and alignment across divisions.
- Leads the organization-wide Data Privacy Committee and participates in privacy-related committees as a subject matter expert.
- Monitors and educates stakeholders on changes in privacy regulations and emerging privacy risks.
2) Compliance Monitoring, Risk Assessment & Controls — 25%
- Performs information privacy risk assessments and conducts ongoing privacy compliance monitoring activities.
- Ensures compliant privacy/confidentiality consents, authorizations, notices, and related materials are maintained.
- Establishes mechanisms to track access to protected health information and enable qualified individuals to review/report such activity.
3) Training, Consultation & Stakeholder Support — 20%
- Provides and/or directs privacy training for employees, volunteers, contractors, business associates, and others.
- Serves as the subject matter expert for the organization in privacy matters, including information blocking.
- Works cooperatively with HIM/Medical Records and others to oversee patient rights related to protected health information (inspect, amend, restrict as appropriate).
4) Incident Response, Investigations & External Reporting — 15%
- Investigates and responds to privacy complaints and possible breaches.
- Leads identification and external reporting of privacy-related noncompliance to regulatory/governmental authorities in coordination with strategic guidance from the Chief Compliance Officer; oversees corrective action plans to remediate issues and prevent recurrence.
- Collaborates with Human Resources in determining sanctions for noncompliance.
5) Contracts, Agreements & Cross-Functional Alignment — 10%
- Reviews, negotiates, and monitors business associate agreements, non-disclosure agreements, and data sharing agreements; reviews/approves privacy-related contracts to ensure regulatory compliance.
- Collaborates with Information Security to review system-related security plans to ensure alignment and consistency with security and privacy practices.
- Monitors advancements in privacy technologies to support organizational adaptation and compliance.
- This job description reflects management’s assignment of essential functions; it does not prescribe or restrict the tasks that may be assigned. The employee may be asked to perform other duties as needed to support departmental and organizational goals.
Education
- Required:
Bachelor of Science in healthcare or a related field. - Preferred:
Juris Doctor (ABA-accredited law school) strongly preferred.
Experience
- Required:
Eight (8) years of relevant experience working in health care privacy.
- Required:
Admitted to the practice of law in the State of Indiana or comparable state. - Preferred:
Certification in Health Care Privacy, Information Privacy, or Healthcare Compliance (CHPC, CIPP/US, CIPM, CHC, or equivalent) strongly preferred.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).